CVE-2016-10362

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
16/06/2017
Last modified:
20/04/2025

Description

Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elasticsearch:output_plugin:*:*:*:*:*:logstash:*:* 5.0.0 (including)